Talent.com
Risk Management Framework (RMF) Analyst
Risk Management Framework (RMF) AnalystGeospatial And Cloud Analytics Inc • Norfolk, VA, US
Risk Management Framework (RMF) Analyst

Risk Management Framework (RMF) Analyst

Geospatial And Cloud Analytics Inc • Norfolk, VA, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]
The RMF Analyst supports OPTEVFOR Cyber Operational Test & Evaluation (OT&E) missions by applying enterprise- and system-level security architecture expertise across the system development lifecycle. The role ensures alignment with evolving laws, regulations, and DoD and Department of the Navy (DoN) cybersecurity policies, and contributes to Risk Management Framework (RMF) activities across all lifecycle phases.


The Security Architect translates complex technical, operational, and environmental requirements into effective security architectures; supports system categorization, policy documentation, security control selection and implementation; and conducts comprehensive assessments of management, operational, and technical security controls to evaluate effectiveness. The position also provides project management and subject matter expertise to guide certification and accreditation (A&A) activities for Cyber OT&E test infrastructure and toolsets, working closely with internal stakeholders and external oversight organizations to ensure timely and compliant system authorizations.


Security Clearance Requirement:
Eligibility for Top Secret / Sensitive Compartmented Information (TS/SCI).


Qualifications
  • Minimum of five (5) years of experience designing and integrating enterprise and system security architectures across the development lifecycle
  • Minimum of three (3) years of experience conducting RMF-related assessments of management, operational, and technical security controls within DoD IT systems
  • Minimum of three (3) years of experience providing project management, subject matter expertise, and hands-on support for system certification and accreditation efforts in accordance with DoD/DoN cybersecurity policies and RMF guidance
Key Responsibilities
Security Architecture and RMF Support
  • Apply enterprise and system-level security architecture principles to support OPTEVFOR Cyber OT&E missions
  • Support RMF activities across all steps, including system categorization, control selection, control implementation, assessment, authorization, and continuous monitoring
  • Provide RMF support consistent with the RMF Process Guide (RPG) for the Information Systems Security Engineer (ISSE) role
  • Evaluate security architectures and designs to determine adequacy and alignment with mission and enterprise objectives
  • Define and document the impact of new systems, interfaces, or changes on overall security posture
Documentation, Compliance, and Governance
  • Create, review, update, and validate cybersecurity Standard Operating Procedures (SOPs)
  • Maintain inventories of authorized software, Government Furnished Equipment (GFE), and removable media
  • Maintain and update all RMF and A&A documentation to ensure accuracy, relevance, and alignment with OPTEVFOR Cyber OT&E assets, including required updates in eMASS
  • Ensure traceability across all RMF artifacts, including:
    • A&A Plans
    • Plans of Action and Milestones (POA&Ms)
    • Security Assessment Reports (SARs)
    • Network topologies
    • Software inventories
    • Ports, protocols, and services
    • Test plans
  • Maintain system and network documentation in DoD IT Portfolio Repository–DoN (DITPR-DON) / DADMS
  • Maintain documentation and registration of network ports, protocols, services, and circuits, including GIAP and SNAP
  • Track and report weekly status of all outstanding A&A actions and supporting documentation
  • As a member of the Configuration Control Board (CCB), ensure approved changes are accurately and timely reflected in A&A documentation
Assessment, Validation, and Hardening
  • Conduct comprehensive annual RMF package reviews to ensure continued compliance of Cyber OT&E toolsets, networks, and systems
  • Execute DISA STIG validations in conjunction with RMF/A&A reviews in accordance with DoDI 8510 series
  • Audit and validate system and network configurations against STIGs; define and implement compensating controls when required to support mission execution
  • Support compliance validation for current and emerging directives (e.g., IAVs, STIGs, TASKORDs, CTOs)
  • Provide recommendations for corrective actions to remediate non-compliant security controls
  • Prepare and maintain vulnerability scan results, system security assessments, and configuration management findings to inform authorization decisions
  • Document assessment activities and results in sufficient detail to support independent external review
Testing, Exercises, and Continuity Planning
  • Develop or contribute to security test plans and supporting documentation to verify security control implementation and inform ongoing risk determinations
  • Conduct and document semi-annual tabletop exercises (twice per calendar year)
  • Review and analyze IT contingency and disaster recovery plans for compliance with NIST and DoN requirements
  • Develop system-specific contingency planning checklists and support contingency plan exercises and training
  • Work independently or in small teams to resolve tasks with minimal supervision
DCWF Knowledge, Skills, Abilities, and Tasks (KSATs)


Knowledge
  • Enterprise information security architecture and IT architectural concepts (baseline and target architectures)
  • Network security architecture principles, protocols, components, and defense-in-depth strategies
  • Cybersecurity-enabled software products and secure configuration management practices
  • RMF processes, documentation, and compliance requirements
  • PII protection standards, program protection planning, and applicable security/privacy regulations
  • Telecommunications concepts, network management principles, and cloud-based security technologies
  • Specialized system requirements, including those supporting critical infrastructure
Skills & Abilities
  • Design and integrate security architectures and frameworks, including multilevel and cross-domain solutions up to TS/SCI
  • Translate laws, regulations, and environmental conditions into effective security designs and processes
  • Perform comprehensive assessments of management, operational, and technical security controls
  • Develop and maintain security compliance processes and audits, including for external services (e.g., cloud providers)
  • Apply cybersecurity methods such as firewalls, DMZs, encryption, PKI, and digital signatures
  • Optimize systems to meet enterprise performance and security requirements
  • Provide project management and subject matter expertise for Cyber OT&E certification and accreditation efforts
  • Document and update security architectures and related artifacts
  • Translate mission capabilities into technical and security requirements and application design elements
  • Provide cost, design, and change-impact advice to program and technical leadership

[job_alerts.create_a_job]

Risk Management Framework RMF Analyst • Norfolk, VA, US

[internal_linking.similar_jobs]
Capability Portfolio Analyst (N)

Capability Portfolio Analyst (N)

SimIS Inc. • Norfolk, VA, US
[job_card.full_time]
[filters_job_card.quick_apply]
Veteran Owned Small Business (VOSB) that models future environments, requirements, and capabilities, and then secures the enterprise from internal and external threats compliant with Federal, State...[show_more]
[last_updated.last_updated_30]
NATO Digital Backbone Systems Analyst (Command Network Systems Analyst)

NATO Digital Backbone Systems Analyst (Command Network Systems Analyst)

Ironclad Defense Works • Norfolk, VA, US
[job_card.full_time]
[filters_job_card.quick_apply]
NATO Digital Backbone Systems Analyst (Command Network Systems Analyst) Location:.Norfolk, VA (On-site at NATO HQ SACT) Employment Type: Full-time, contractor support (contingent upon contract awar...[show_more]
[last_updated.last_updated_variable_days]
Survey Taker: Earn up to $25 per survey (Remote)

Survey Taker: Earn up to $25 per survey (Remote)

Earn Haus • Gloucester Point, VA, US
[filters.remote]
[job_card.full_time] +1
Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se...[show_more]
[last_updated.last_updated_30] • [promoted]
Life Actuarial Solutions Analyst Lead

Life Actuarial Solutions Analyst Lead

USAA • Chesapeake, VA, United States
[job_card.full_time]
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice.We seek to be the #1 choice for the military...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Exploitation Analyst

Exploitation Analyst

Watershed Security • Norfolk, VA, US
[job_card.full_time]
[filters_job_card.quick_apply]
JOB DESCRIPTION Watershed Security, is a Veteran Owned Small Business with over 20 years’ Cybersecurity and Government Contracting experience.Watershed is looking for an Exploitation Analyst to dev...[show_more]
[last_updated.last_updated_variable_days]
Store Safety Specialist

Store Safety Specialist

Family Dollar • Chesapeake, VA, United States
[job_card.full_time]
Based in Chesapeake, VA, Family Dollar operates more than 7,000 stores across the 48 contiguous states, supported by a coast-to-coast logistics network and more than 80,000 Associates.Family Dollar...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Mortgage Occupancy Field Inspector

Mortgage Occupancy Field Inspector

GIS Field Services • Port Haywood, VA, United States
[job_card.full_time]
Mortgage Occupancy Field Inspectors.Our independent contractors enjoy a flexible schedule while earning weekly pay.Please visit our website to learn more about us and the industry.Mortgage Occupanc...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Analyst, Management-Mid

Analyst, Management-Mid

International Executive Service Corps • Norfolk, VA, United States
[job_card.full_time]
SEA 21, NAVSEA’s Director of Surface Ship Maintenance, Modernization, and Sustainment is seeking professional support services (PSS) to support the Government's existing organization, personnel, kn...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Database Management Analyst lll

Database Management Analyst lll

ENGINEERING SERVICES NETWORK, Inc. • Chesapeake, VA, USA
[job_card.full_time]
[filters_job_card.quick_apply]
Founded in 1995, ESN is a Small Disadvantaged Business (SDB), Service-Disabled Veteran-Owned Small Business (SDVOSB) and Veteran Owned Small Business (VOSB).ESN delivers trusted solutions that supp...[show_more]
[last_updated.last_updated_30]
Store Safety Specialist

Store Safety Specialist

Dollar Tree • Chesapeake, VA, United States
[job_card.full_time]
Based in Chesapeake, VA, Family Dollar operates more than 7,000 stores across the 48 contiguous states, supported by a coast-to-coast logistics network and more than 80,000 Associates.Family Dollar...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Management Analyst II

Management Analyst II

Synectic Solutions Inc • Norfolk, VA, US
[job_card.full_time]
[filters_job_card.quick_apply]
The Management Analyst II provides mid-level analytical support to help the Government identify, assess, and improve organizational performance, operational processes, and decision-making.This role...[show_more]
[last_updated.last_updated_30]
Digital Backbone Systems Analyst (Command Network Systems Analyst)

Digital Backbone Systems Analyst (Command Network Systems Analyst)

Techlink Systems Inc. • Norfolk, VA, United States
[job_card.full_time]
[filters_job_card.quick_apply]
Job Title: Digital Backbone Systems Analyst (Command Network Systems Analyst) Location (On-site, Remote, or Hybrid?): Norfolk, VA (onsite) Contract Duration: Contract until 12/31/3030 [show_more]
[last_updated.last_updated_variable_hours] • [new]
Capabilities and Limitations Researcher

Capabilities and Limitations Researcher

Advanced Computer Learning Company • Hampton, VA, USA
[job_card.full_time]
[filters_job_card.quick_apply]
ACLC is looking for an experienced Capabilities and Limitations Researcher with a deep understanding of the USAF Tactical Datalink Configuration and Logistics process and tools to provide TDL opera...[show_more]
[last_updated.last_updated_variable_days]
Microsoft Dynamics Finance Functional Analyst

Microsoft Dynamics Finance Functional Analyst

Abacus • Norfolk, VA, United States
[job_card.full_time]
Microsoft Dynamics Finance Functional Analyst.Job Title: Microsoft Dynamics Finance Functional Analyst.Client: Transportation District Commission of Hampton Roads.Place of Performance: Hampton Road...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Spectrum Management Analyst

Spectrum Management Analyst

ANALYGENCE • Hampton, VA, United States
[job_card.full_time]
Headquarters Air Combat Command (HQ ACC) at Langley Air Force Base.Support includes a full range of Information Warfare training and operations, Information Systems & Operations, Communications, Ad...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
NATO Digital Backbone Systems Analyst (Command Network Systems Analyst)

NATO Digital Backbone Systems Analyst (Command Network Systems Analyst)

DEFTEC Corporation • Norfolk, VA, USA
[job_card.full_time]
[filters_job_card.quick_apply]
NATO Digital Backbone Systems Analyst (Command Network Systems Analyst).DEFTEC delivers mission-critical solutions through skillfully delivered services and innovative products.We are inspired by o...[show_more]
[last_updated.last_updated_variable_days]
Management Analyst I

Management Analyst I

Synectic Solutions Inc • Norfolk, VA, US
[job_card.full_time]
[filters_job_card.quick_apply]
The Management Analyst I supports organizational decision-making by collecting, reviewing, and analyzing data to identify issues, evaluate processes, and recommend improvements.This role assists in...[show_more]
[last_updated.last_updated_30]
Cyber Security Analyst

Cyber Security Analyst

Marine Hydraulics International, LLC • norfolk, va, us
[job_card.full_time]
MHI Ship Repair & Services is a major marine repair and conversion contractor serving the U.Navy, Military Sealift Command, Maritime Administration and Commercial ship owners and operators worldwid...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]